Controlling Information Systems: IT Processes:

In chapter 8 we look at Controls specifically designed for the Information Systems Function.

COBIT

(What is this?) IT resources:
  • Data
  • Application sytems
  • Technology
  • Facilities
  • People

COBIT's defintion of Control:

Information Systems Function (ISF):

Define, what is this?
Types of Organizational structurs for ISF:
  • Centralized
  • Decentralized
  • Functional
  • Matrix
  • Project

Summarize the key control concerns (similar to business exposures) for the various ISF functions (see if you can combine similar concerns by hierarchical layer in the organization chart).

COBIT Control Process Domains:

  • Planning and Organization
    • Process#1
    • Process#2
  • Acquistion and Development
    • Process#3
    • Process#4
    • Process#5
    • Process#6
  • Delivery and Support
    • Process#7
    • Process#8
    • Process#9
  • Monitoring
    • Process#10


Segrgation of Duties:


Segregating Events Processing:
Segregating Information Systems Functions:

Personnel control Plans:

  • Key Control Issues:
  • Selecting and Hiring Plans
  • Retention Plans
  • Personnel Development Plans
  • Personnel Management Plans